
artillery
Open-source blue team tool that protects Linux and Windows systems using multiple host and network defense and detection methods.

Open-source blue team tool that protects Linux and Windows systems using multiple host and network defense and detection methods.

Open-source detection engineering tool that traces security detections end to end and identifies the first failing stage.

An eBPF-powered Active Defense system that turns your Linux server into a deceptive honeypot. Features transparent traffic redirection, OS…

PowerShell-based backdoor detection tool for VMware Horizon connection servers, targeting CVE-2021-44228. Includes canary with optional submission…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection,…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Small tool to play with IOCs caused by Imageload events

Detection rule validation

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Windows Analysis and Research Toolkit

A binary and file access authorization system for macOS.

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Automated Network Security with Rust: Detecting and Blocking Port Scanners

A Go library for using zeek broker's websocket API

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Corelight@Home script

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.